Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.57% | — | ApolloAI | 15/7/2026 | 15/7/2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under… | |
| Aplazada | Alta (7.5) | 0.57% | — | ApolloAI | 15/7/2026 | 15/7/2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because ConfigService can accept a non-canonical appId… | |
| Aplazada | Media (6.5) | 0.41% | — | ApolloAI | 15/7/2026 | 29/9/2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (8.1) | 0.34% | — | Apollographql Apollo MCP Server | 9/4/2026 | 17/6/2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requests when using StreamableHTTP transport. In configurations where an HTTP-based MCP server is run on localhost without… | |
| Aplazada | Crítica (9.9) | 0.56% | — | Apollo FederationAI | 16/3/2026 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute… | |
| Aplazada | Alta (8.1) | 0.56% | — | Ancorathemes Apollo Night Club DJ Event Wordpress ThemeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Apollo | Night Club, DJ Event WordPress Theme apollo allows PHP Local File Inclusion.This issue affects Apollo | Night Club, DJ Event WordPress Theme: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.4) | 0.31% | — | Apollo13 Framework ExtensionsAI | 19/2/2026 | 17/6/2026 | The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Alta (7.5) | 0.65% | — | Apollographql Apollo Server | 4/2/2026 | 17/6/2026 | Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to… | |
| Aplazada | Media (6.6) | 0.41% | — | Palantir AriesAIPalantir ApolloAI | 22/1/2026 | 17/6/2026 | A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system… | |
| Aplazada | Alta (7.5) | 0.38% | — | Apollo FederationAIApollo RouterAIAvirt RoverAI | 13/11/2025 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation… | |
| Aplazada | Alta (7.5) | 0.30% | — | Apollo Router CoreAI | 7/11/2025 | 17/6/2026 | Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that… | |
| Aplazada | Alta (7.5) | 0.32% | — | Apollo Router CoreAI | 6/11/2025 | 17/6/2026 | Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access controls. Router… | |
| Aplazada | Alta (8.2) | 0.16% | — | Apollo SandboxAISpeed Software ExplorerAI | 26/9/2025 | 17/6/2026 | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the… | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Apollo Sticky Full Width Html5 Audio PlayerAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through <= 3.4. | |
| Analizada | Alta (8.7) | 0.66% | — | Apollotheme AP Pagebuilder | 8/5/2025 | 17/6/2026 | Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system. | |
| Aplazada | Alta (7.5) | 0.56% | — | Apollo RouterAITarget CompilerAI | 9/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This… | |
| Aplazada | Alta (7.5) | 0.53% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, a vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan,… | |
| Aplazada | Alta (7.5) | 0.57% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, the operation limits plugin uses unsigned 32-bit integers to track limit counters (e.g. for a query's height). If a counter exceeded the… | |
| Aplazada | Alta (7.5) | 0.57% | — | Apollo RouterAI | 7/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal… | |
| Analizada | Alta (7.5) | 0.58% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being… | |
| Analizada | Alta (7.5) | 0.51% | — | Apollographql Apollo Gateway | 7/4/2025 | 17/6/2026 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion.… | |
| Aplazada | Alta (7.5) | 0.42% | — | Apollo CompilerAI | 7/4/2025 | 17/6/2026 | apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. Named fragments were being processed once per fragment spread in some cases during query… | |
| Aplazada | Crítica (9.3) | 0.56% | — | Gmod ApolloAI | 5/3/2025 | 17/6/2026 | Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username | |
| Aplazada | Crítica (9.3) | 0.66% | — | Gmod ApolloAI | 5/3/2025 | 17/6/2026 | When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types. |